fix(auth): fail closed configuration compatibility
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
import { expect, test } from "vitest";
|
||||
import { mkdtempSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { stringify } from "yaml";
|
||||
import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
|
||||
test("configured OIDC fails app startup until an OIDC handler is installed", () => {
|
||||
const directory = mkdtempSync(join(tmpdir(), "thothii-app-oidc-mode-"));
|
||||
const file = join(directory, "auth.yaml");
|
||||
writeFileSync(file, stringify({
|
||||
version: 1, mode: "oidc", publicUrl: "https://thothii.example.org",
|
||||
oidc: {
|
||||
issuer: "https://authentik.example.org/application/o/thothii/", clientId: "thothii",
|
||||
clientSecretRef: "THT_OIDC_CLIENT_SECRET", scopes: ["openid"], groupsClaim: "groups",
|
||||
},
|
||||
groupCatalog: { driver: "authentik", baseUrl: "https://authentik.example.org", apiTokenRef: "THT_AUTHENTIK_API_TOKEN" },
|
||||
authorization: { groupRoles: { "TOT Users": ["user"], "TOT Admin": ["admin"] } },
|
||||
}), "utf8");
|
||||
try {
|
||||
expect(() => buildApp(loadConfig({ THT_AUTH_CONFIG_FILE: file })))
|
||||
.toThrow("configured authentication mode is not implemented");
|
||||
} finally {
|
||||
rmSync(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user